Re: Security techniques
| From: | Zeev Suraski | Date: | Mon, 30 Jul 2001 01:29:17 +0000 |
| Subject: | Re: Security techniques | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61411@lists.php.net to get a copy of this message | ||
At 12:04 29/07/2001, Stephen van Egmond wrote:
2. when a uploaded file fails is_uploaded_file().My English parser bailed out on this one :)
I felt bad when I saw is_uploaded_file() introduced - it is such a cheezy function call; people shouldn't even have to call it themselves, and I can imagine no situation (except for laziness) that you would not call it.While it may be rare to find a situation in which it's useful more than move_uploaded_file(), these cases do exist. I'm not sure what's wrong with it, can you be more specific? Zeev